hashicorp / hashicorp/vault-helm

Vault doesn't Initialize with Auto-unseal using Transit Secrets Engine

Open
#480 1 comment 0 reactions 0 assignees View on GitHub
bug
Dominant language
Shell
Stars
1.3k
Forks
898
Avg merge
3d 1h
Merged PRs (30d)
1

Description

Configured Vault using Auto-unseal using Transit Secrets Engine.

As mentioned in the following doc I've configured multiple vaults and everything seems to be working fine.
https://learn.hashicorp.com/tutorials/vault/autounseal-transit?in=vault/auto-unseal

Vault A ( This is configured to use for unsealing the Vault B as mentioned in the above doc )
Vault B ( This is the actual vault where we store stuff... )

After Vault is up and running I tried the validating the following scenario.

What if I lost the unseal vault server (Vault A )?
- I got to know that we can recover the vault server ( Vault B ) with the **recovery key** which we get while initializing vault ( Vault B ).
- In Vault server ( Vault B) first I tried sealing the vault manually, unsealing it using recovery key and this worked fine. ✔️
- Now I stopped the unseal vault server ( Vault A) and restarted the vault server ( Vault B ) and trying to unseal it with recovery key ( which i got when vault B is initialized ) gives me connection refused.

I believe vault should come up with initialized, sealed mode so that I can unseal with the recovery key but that doesn't seems to happen in my case.

Am i missing anything here ?

Contributor guide

Open the contributing guide

Research direction

Start with the linked Vault auto-unseal Transit tutorial and the Vault A/Vault B setup described in the issue. Reproduce the restart of Vault B while Vault A is unavailable, then compare manual sealing and recovery-key behavior; done means the expected initialized, sealed state and recovery path are confirmed or the missing configuration is identified.

Written by the indexing model from the issue text.

Assessment

Tech stack
helm
Domain
infrastructure, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.